Slacker News Slacker News logo featuring a lazy sloth with a folded newspaper hat
  • top
  • new
  • show
  • ask
  • jobs
Library

Comment by h4kunamata

2 days ago

Still compromised: https://socket.dev/blog/trivy-under-attack-again-github-acti...

This is a very old vulnerability, and to see companies falling for it is mental.

The year is 2026 and companies are still using tag over hash. It is well known that you can release different code under the same tag without alerting users.

0 comments

h4kunamata

Reply

No comments yet

Contribute on Hacker News ↗

Slacker News

Product

  • API Reference
  • Hacker News RSS
  • Source on GitHub

Community

  • Support Ukraine
  • Equal Justice Initiative
  • GiveWell Charities